LXC Meets Docker? And Other Questions About Proxmox 9.1
Proxmox VE 9.1 just dropped, and as usual the update brings more than a version bump. If you've been following the chatter online, there's excitement, hesitation, and a whole lot of curiosity, most of it around one shiny new feature: creating LXC containers directly from OCI images. For the uninitiated, that's basically a way to pull Docker-like containers into the Proxmox world.
Proxmox 9.2: Finally Fixing the LXC Permission Nightmare!
That's only the tip of the iceberg, though. From TPM tweaks to better SDN reporting, there's plenty to unpack, so instead of dumping a changelog we've rounded up the biggest questions people are asking about Proxmox 9.1 and answered them straight.
Q: What's the big deal with LXC containers from OCI images? Is this Docker now?
Kind of. The new feature lets you spin up LXC containers using images from OCI registries, yes, like Docker Hub. Don't toss out your Docker setup just yet, though.
Right now it's a tech preview, which means it's experimental and a bit rough around the edges. You can pull images and launch containers, but complex things like docker-compose, native volume management, or full network config aren't there yet. Think of it as "Docker-adjacent with Proxmox flavor" more than "Docker on Proxmox."
Still, it's a huge step. Many users got things like Grafana, Nextcloud, or Nginx containers running without much hassle. Others hit limitations, especially when containers needed more than environment variables to configure or expected Docker's layered filesystem behavior.
In short, it's promising. If all goes well, this could reduce the need to run Docker inside an LXC or a full VM, giving you better resource efficiency without ditching Proxmox's control layer.
Q: Is this update stable? Should I upgrade now or wait?
The consensus is mostly stable, with caveats. People already on version 9 report smooth sailing with the 9.1 upgrade, though there are some horror stories about BIOS settings, failed boots, and mysterious segfaults on specific setups. Most of those issues seem tied to underlying hardware quirks or to users skipping steps like the pve8to9 checks.
One user summed it up best: "I worked in IT long enough to know never to be the first nor the last to upgrade."
So, if you're on 8.x:
- Yes, it's safe, as long as you follow the upgrade documentation to the letter.
- No, if you're tired, under-caffeinated, and trying this at 11PM on production nodes.
Q: Wait, what's with the TPM changes?
Proxmox VE 9.1 adds support for TPM state in qcow2 format. That might sound niche, but it matters for anyone running Windows VMs with secure boot or other modern security features.
It's especially relevant if you snapshot or migrate VMs that rely on TPM. In earlier versions, snapshots and backups didn't always play nice with TPM-enabled machines, and now that data can be stored properly.
One warning: you can't create a snapshot of a running VM with TPM, at least not yet. You'll need to shut down the VM first.
Q: What else is actually new in 9.1?
Here are a few highlights you might care about:
- New vCPU flags for fine-grained control of nested virtualization (a win for dev/test environments).
- Better SDN status reporting, especially if you're using Proxmox's software-defined networking features.
- Improvements to the web UI, including better upgrade notifications and container handling.
- Kernel updates, which improve compatibility and performance but can break older NFS client setups if you're not careful.
There's also better handling of /proc and /sys in nested container environments, which fixes an issue that had been blocking certain Docker containers from running properly inside LXC.
Q: Does this fix the Docker-in-LXC AppArmor issue?
Yes, but it depends on your setup. The infamous apparmor + runc combo that broke Docker in LXCs has been a recurring problem, especially for users running Debian 13. The 9.1 update lifts some AppArmor restrictions when nesting is enabled, which fixes the issue for unprivileged containers.
The bug itself sits upstream in Docker/runc/AppArmor, not in Proxmox. Workarounds included downgrading runc, switching to Alpine, or just moving containers to VMs. With this update many of those headaches go away, as long as you restart your containers after updating.
Q: Are VMs or LXCs better now for Docker?
The debate rages on. Some say running Docker in a full VM (especially on Alpine) gave them better performance than LXCs, while others argue that should never happen unless your LXC is misconfigured.
One user suggested that a cleaner environment, CPU pinning, and NUMA awareness made their Docker-on-VM setup snappier than Docker-in-LXC ever was.
So it depends on your workload. For quick-and-dirty web servers, LXC might still be fine. For anything needing heavy I/O, encryption, or tight kernel control, VMs still win.
For a fuller breakdown of when to reach for plain LXC, Docker-in-LXC, or Docker-in-VM, see our LXC vs VM vs Docker decision guide.
Q: So is this a step toward replacing Docker entirely in Proxmox?
Maybe eventually. Right now it's more of a side-step than a full replacement.
There's hope that future versions will bring better volume mapping, container orchestration (think mini docker-compose), and maybe even direct Docker API integration. Today, though, Proxmox's OCI feature is more like a smarter bridge between its container engine and the modern container ecosystem.
Q: Anything else to watch out for in this release?
A few things to watch:
- NFS stability. Some users saw nodes hang under heavy NFS load with the new kernel, while others reported zero issues. If you rely heavily on NFS, proceed with caution or test first.
- Boot priority glitches. A handful of folks found their BIOS boot priorities flipped after the upgrade.
- No support yet for snapshotting running TPM-enabled Windows VMs, so you'll still need to shut them down.
And as always, don't skip the pve8to9 validation script. It can catch old configs or leftover packages that might cause problems mid-upgrade.
Q: TL;DR, should I upgrade to 9.1?
If you're running Proxmox in a home lab or another non-critical setup, go for it. The new features, OCI support in particular, are worth checking out.
If you're managing production clusters, test it first, and wait a week or two if you're not in a rush.
And if you're someone who gets a thrill from watching the world burn, sure, upgrade live at midnight without reading the docs. Just don't say we didn't warn you.
Final thoughts
Proxmox VE 9.1 feels like a bridge between where virtualization was and where it's headed. Docker-style LXC containers, TPM-aware snapshots, and more granular SDN controls all hint at a more integrated, container-friendly future.
For now, that future is still in preview. If you enjoy playing with new toys and don't mind a little trial and error, this release is a playground. If stability is king, give it a minute.
In the meantime, keep an eye on those OCI images. Proxmox is staying Proxmox, and it's definitely learning to speak Docker's language.